<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Misclib Tech Blog</title>
    <link>https://www.misclib.com/blog/</link>
    <description>生成AIの法人導入とセキュリティ統制を、各社の公式ドキュメントを確かめながら解説する Misclib のテックブログ。</description>
    <language>ja</language>
    <lastBuildDate>Sat, 10 Oct 2026 01:36:44 GMT</lastBuildDate>
    <atom:link href="https://www.misclib.com/blog/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>ChatGPT Business を外部サービスで補完して Enterprise に近づける — できること・できないことの線引き</title>
      <link>https://www.misclib.com/blog/chatgpt-business-to-enterprise-grade/</link>
      <guid isPermaLink="true">https://www.misclib.com/blog/chatgpt-business-to-enterprise-grade/</guid>
      <description>SCIM、監査ログ、接続元制限、Compliance API、テナント制限。ChatGPT Business に足りない統制を、IdP・セキュア Web ゲートウェイ・ブラウザ・MDM でどこまで補えるかを、公式ドキュメントで確かめながら整理する。</description>
      <category>プラン選定</category>
      <pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Claude Team を外部サービスで補完して Enterprise に近づける — テナント制限が使えない前提での設計</title>
      <link>https://www.misclib.com/blog/claude-team-to-enterprise-grade/</link>
      <guid isPermaLink="true">https://www.misclib.com/blog/claude-team-to-enterprise-grade/</guid>
      <description>Claude Team には SCIM、監査ログ、Compliance API、テナント制限がない。IdP・セキュア Web ゲートウェイ・MDM・OpenTelemetry でどこまで補えるか、Team ならではの制約とあわせて公式ドキュメントで確かめながら整理する。</description>
      <category>プラン選定</category>
      <pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>「SSO がある」と「統制できる」は別物 — 法人向け生成AIプランの層をどう選ぶか</title>
      <link>https://www.misclib.com/blog/sso-is-not-governance/</link>
      <guid isPermaLink="true">https://www.misclib.com/blog/sso-is-not-governance/</guid>
      <description>ChatGPT Business と Claude Team は SSO まで。SCIM、監査ログ、接続元制限はプランの機能としてはエンタープライズ層に限られる。IdP やゲートウェイで補える範囲と、補えない範囲を整理する。</description>
      <category>プラン選定</category>
      <pubDate>Fri, 09 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>法人プランを入れても個人アカウントに逃げられる — テナント制限ヘッダで持ち出しを塞ぐ</title>
      <link>https://www.misclib.com/blog/block-personal-ai-accounts/</link>
      <guid isPermaLink="true">https://www.misclib.com/blog/block-personal-ai-accounts/</guid>
      <description>社員が同じブラウザで個人の ChatGPT・Claude・Gemini にログインし直せば、統制の外に出る。3社が用意しているプロキシでのヘッダ付与による対策と、その限界をまとめる。</description>
      <category>ID・入口の統制</category>
      <pubDate>Fri, 09 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>同意画面1回で会社の Drive が外部 AI につながる — 認証基盤で止める設定と、ChatGPT の Drive 接続の正しい組み方</title>
      <link>https://www.misclib.com/blog/idp-oauth-consent-control/</link>
      <guid isPermaLink="true">https://www.misclib.com/blog/idp-oauth-consent-control/</guid>
      <description>「Google でログイン」の同意を1回押すだけで、社内の Drive や SharePoint を外部の AI サービスにつなげられる。AI サービス側では止められないこの経路を、Google Workspace と Entra ID で統制する。</description>
      <category>ID・入口の統制</category>
      <pubDate>Fri, 09 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>「DLP あり」でもプロンプトは止まらない — 生成AIにおける DLP の3つの型</title>
      <link>https://www.misclib.com/blog/ai-dlp-three-types/</link>
      <guid isPermaLink="true">https://www.misclib.com/blog/ai-dlp-three-types/</guid>
      <description>入力の検査、参照元の制限、事後検知。生成AIの DLP は3つの型に分かれ、提供元ごとに対応する型が違う。「個人情報の貼り付けを止めたい」なら、どの型が必要かを整理する。</description>
      <category>データ保護</category>
      <pubDate>Fri, 09 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>社内データ・外部コンテンツ・外部送信 — 3つが揃うと AI から情報が流出する</title>
      <link>https://www.misclib.com/blog/ai-exfiltration-three-conditions/</link>
      <guid isPermaLink="true">https://www.misclib.com/blog/ai-exfiltration-three-conditions/</guid>
      <description>プロンプトインジェクションによる情報流出は、3つの条件が揃ったときに起きる。全部は禁止できないので、最も効く「外部送信」を絞る。各社のコード実行・クラウド実行のネットワーク設定を整理する。</description>
      <category>エージェント・外部接続</category>
      <pubDate>Fri, 09 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>コーディングエージェントの既定値は安全側とは限らない — Claude Code・Codex・Antigravity の管理設定</title>
      <link>https://www.misclib.com/blog/coding-agent-managed-settings/</link>
      <guid isPermaLink="true">https://www.misclib.com/blog/coding-agent-managed-settings/</guid>
      <description>Claude Code は自動承認の auto モードが既定、Antigravity はターミナル自動実行が「Always proceed」でサンドボックスは既定オフ。開発者向けエージェントを MDM で統制するための設定の勘所をまとめる。</description>
      <category>コーディングエージェント</category>
      <pubDate>Fri, 09 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>「国内保存」と「国内処理」は別物 — 生成AIのデータレジデンシーと ISMAP の現実</title>
      <link>https://www.misclib.com/blog/data-residency-and-ismap/</link>
      <guid isPermaLink="true">https://www.misclib.com/blog/data-residency-and-ismap/</guid>
      <description>日本に保存できても、推論は海外というケースが多い。チャット製品と API で取れる経路も違う。国内要件と ISMAP 要件を、どの製品・経路で満たせるかを整理する。</description>
      <category>データ保護</category>
      <pubDate>Fri, 09 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>チーム層で会話本文ログと入力検査を補う — Cloudflare を使ったネットワーク側の代替構成</title>
      <link>https://www.misclib.com/blog/team-tier-network-logging/</link>
      <guid isPermaLink="true">https://www.misclib.com/blog/team-tier-network-logging/</guid>
      <description>Compliance API や入力の検査はエンタープライズ層の機能。ChatGPT Business や Claude Team でも、通信経路にゲートウェイを挟めば近い水準の記録と検査を構築できる。2つの構成と限界を解説する。</description>
      <category>ネットワーク・監査</category>
      <pubDate>Fri, 09 Oct 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
